Courseiva
Fundamental Cloud Concepts →mediumMultiple Select

Cloud Digital Leader Fundamental Cloud Concepts Practice Question

A healthcare organization must store patient health records (PHI) in the cloud and comply with HIPAA. They need to ensure data is encrypted at rest by default, maintain access logs, and restrict access to authorized personnel. Which THREE Google Cloud features or services should they use?

⚠ Common exam trap

GCDL often tests whether candidates can distinguish network-observability services (VPC Flow Logs, Cloud NAT) from the three pillars of PHI compliance — audit logging, identity/access control, and encryption key management — so avoid picking networking tools for a data-protection question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Audit Logs

Cloud Audit Logs (A) are correct because they record Admin Activity, Data Access, System Event, and Policy Denied audit logs for Google Cloud services, providing the access logging and monitoring evidence HIPAA requires for PHI. Identity and Access Management (B) is correct because IAM lets the organization enforce least-privilege access via roles, policies, and conditions so that only authorized personnel can reach the PHI resources. Cloud Key Management Service (E) is correct because Cloud KMS manages the encryption keys used for data at rest, including customer-managed encryption keys (CMEK) and key rotation, satisfying the requirement for default encryption at rest under organizational control. VPC Flow Logs (C) is not correct because it captures network-level IP traffic metadata for subnets, not the resource access audit trail needed for PHI compliance. Cloud NAT (D) is not correct because it only provides outbound internet connectivity for private instances and has no role in encryption, access control, or audit logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Audit Logs

    Why this is correct

    Cloud Audit Logs are the definitive record of 'who did what, where, and when' in Google Cloud. For HIPAA-covered entities, enabling Data Access audit logs is mandatory to capture every read, write, and deletion of patient records, providing the auditable trail required by the Security Rule. Admin Activity logs track configuration changes, and System Event logs record system-level actions, all of which support security monitoring and incident forensics.

  • ✓

    Identity and Access Management (IAM)

    Why this is correct

    Cloud IAM controls who is authenticated and authorized to interact with PHI-storing resources like Cloud Storage buckets or BigQuery datasets. By assigning fine-grained roles (e.g., storage.objectViewer vs. storage.admin) and applying conditions such as IP-address or scheduled-time restrictions, organizations enforce least privilege and separation of duties. This directly supports HIPAA's Access Control standard by limiting exposure to patient data only to authorized personnel.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture network-level metadata such as source/destination IP addresses, ports, and protocol, but they cannot identify a specific user or whether they accessed a particular patient record. While useful for detecting anomalous network traffic or investigating network-layer attacks, they do not satisfy HIPAA's audit control requirement because they lack the user-identity and resource-access context found in Cloud Audit Logs.

  • ✗

    Cloud NAT

    Why it's wrong here

    Cloud NAT is a networking service that enables outbound internet connections from private instances without assigning them public IP addresses. It does not perform encryption, manage cryptographic keys, or enforce access control on PHI, so it is irrelevant to HIPAA's technical safeguards. Its function is purely address translation and has no bearing on confidentiality, integrity, or availability of patient data.

  • ✓

    Cloud Key Management Service (Cloud KMS)

    Why this is correct

    Cloud KMS is the centralized key management service for encrypting data at rest in Google Cloud. HIPAA requires encryption of ePHI, and Cloud KMS lets you create, rotate, and destroy keys while controlling access to those keys via IAM roles. It integrates with services like Cloud Storage and BigQuery, ensuring that even if underlying storage is compromised, patient data remains unreadable without the proper keys.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.